Actively Exploited, CISA KEV

CVE-2023-27351: PaperCut NG/MF Vulnerability

Severity: Unknown | CVSS 3.1: N/A | KEV Added: 2026-04-20

What is CVE-2023-27351?

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Impact Analysis

Exploitation Probability (EPSS): 78.4% chance of exploitation in the next 30 days (100th percentile). This places the vulnerability in the highest risk tier, immediate action is critical.

Is CVE-2023-27351 being exploited?

Yes. CVE-2023-27351 is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, restricted to CVEs with confirmed active exploitation in the wild. CISA added this vulnerability on 2026-04-20. Inclusion in KEV triggers the patching mandate under BOD 22-01 for U.S. federal civilian agencies, with a remediation deadline of 2026-05-04.

How to fix CVE-2023-27351

Apply the security update issued by PaperCut for NG/MF. If an immediate patch is not possible, consult the vendor advisory for mitigation guidance, restrict network exposure of the affected service, and monitor logs for indicators of exploitation. CISA's Known Exploited Vulnerabilities catalog requires U.S. federal agencies to remediate this vulnerability by the due date shown below under Binding Operational Directive 22-01. Private organizations should treat KEV entries as priority-one patches because active exploitation has been confirmed in the wild.

Related Vulnerabilities

Other actively exploited vulnerabilities affecting NG/MF:

  • CVE-2023-2533 (High 8.4) [same product], A Cross-Site Request Forgery (CSRF) vulnerability has been identified…

Frequently asked questions

Is CVE-2023-27351 critical?

CVE-2023-27351 has a CVSS 3.1 base score of N/A, Unknown severity. Prioritize based on exposure and the active exploitation signal from the KEV listing.

Is CVE-2023-27351 being actively exploited?

Yes, CISA added CVE-2023-27351 to the Known Exploited Vulnerabilities catalog on 2026-04-20. Inclusion in KEV means CISA has confirmed in-the-wild exploitation.

How do I patch CVE-2023-27351?

Apply the security update from PaperCut for NG/MF. Federal agencies must remediate by 2026-05-04 under BOD 22-01.

What is the CVSS score for CVE-2023-27351?

CVE-2023-27351 has a CVSS 3.1 base score of N/A, classifying it as Unknown severity.